Marketing site

  • No cookies.
  • No analytics beacon, tracking pixel, or third-party font/script.
  • One localStorage key, coffre-theme, for light/dark mode.
  • Server access logs are used for operations and abuse diagnosis.

Hosted app account data

Hosted Coffre stores account email, device records, passkey public credentials, Apple identity links when you choose to link them, sessions, encrypted vault operation logs, encrypted context metadata, push-token registrations, and billing entitlement rows.

What the server cannot read

TOTP seeds, generated codes, generic secret values, item names, issuers, accounts, context names, master passwords, recovery keys, and vault decryption keys stay client-side or encrypted. The server stores ciphertext and sync metadata only.

Hosted billing metadata

The free hosted plan allows 10 TOTP tokens and no generic secrets. To enforce that without decrypting your vault, hosted clients attach an item_type value of totp or secret to item-scoped sync operations. The server can count item categories. It still cannot read the encrypted item contents.

Payment providers

Web subscriptions use Mollie checkout. Renewal is managed in Coffre. Coffre stores the provider name, customer id, subscription id, tier, payment identifiers, and current billing period end. Coffre sends the account email to Mollie to create a billing customer. Card details stay with Mollie. Apple and Google purchase verification stores the same account-level entitlement metadata after validating the native purchase with the provider.

Email

If you reach out via hello@coffre.app or security@coffre.app, we keep your message as long as it's useful to answer you.

Self-hosting

If you self-host Coffre, your chosen operator controls server logs, database retention, backups, TLS termination, and any payment or access policy they add around their instance. The AGPL software ships with hosted billing disabled by default.

Contact

hello@coffre.app